First published: Tue Nov 08 2022(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Vladimir Anokhin's Shortcodes Ultimate plugin <= 5.12.0 on WordPress.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Shortcodes Ultimate by Vova Anokhin | <=5.12.0 |
Update to 5.12.1 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41136 is a Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in the Shortcodes Ultimate plugin <= 5.12.0 on WordPress.
CVE-2022-41136 has a severity rating of 8.8 (high).
The Shortcodes Ultimate plugin versions up to and including 5.12.0 on WordPress are affected by CVE-2022-41136.
To fix CVE-2022-41136, update the Shortcodes Ultimate plugin to a version higher than 5.12.0.
You can refer to the following links for more information on CVE-2022-41136: [Patchstack](https://patchstack.com/database/vulnerability/shortcodes-ultimate/wordpress-shortcodes-ultimate-plugin-5-12-0-csrf-vulnerability-leading-to-stored-xss?_s_id=cve) and [WordPress Plugin Directory](https://wordpress.org/plugins/shortcodes-ultimate/#developers).